← Back to catalog
AC-2(11)

Usage Conditions

Access Control (AC)
Baselines
Low · Not includedModerate · Not includedHigh · Included
Description

Enforce [assignment] for [assignment].

Discussion

Specifying and enforcing usage conditions helps to enforce the principle of least privilege, increase user accountability, and enable effective account monitoring. Account monitoring includes alerts generated if the account is used in violation of organizational parameters. Organizations can describe specific conditions or circumstances under which system accounts can be used, such as by restricting usage to certain days of the week, time of day, or specific durations of time.

Implementation guidance

No content available.

CSF 2.0 crosswalk

No CSF mappings exist for this control.